Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareCOATHANGER | COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices. |
| T1027 Obfuscated Files or Information |
MalwareCOATHANGER | COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`. |
| T1027.002 Software Packing |
MalwareCOATHANGER | The first stage of COATHANGER is delivered as a packed file. |
| T1055 Process Injection |
MalwareCOATHANGER | COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library. |
| T1057 Process Discovery |
MalwareCOATHANGER | COATHANGER will query running process information to determine subsequent program execution flow. |
| T1059.004 Unix Shell |
MalwareCOATHANGER | COATHANGER provides a BusyBox reverse shell for command and control. |
| T1070.004 File Deletion |
MalwareCOATHANGER | COATHANGER removes files from victim environments following use in multiple instances. |
| T1071.001 Web Protocols |
MalwareCOATHANGER | COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control. |
| T1083 File and Directory Discovery |
MalwareCOATHANGER | COATHANGER will survey the contents of system files during installation. |
| T1095 Non-Application Layer Protocol |
MalwareCOATHANGER | COATHANGER uses ICMP for transmitting configuration information to and from its command and control server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCOATHANGER | COATHANGER decodes configuration items from a bundled file for command and control activity. |
| T1190 Exploit Public-Facing Application |
MalwareCOATHANGER | COATHANGER is installed following exploitation of a vulnerable FortiGate device. |
| T1222.002 Linux and Mac Permissions |
MalwareCOATHANGER | COATHANGER will set the GID of `httpsd` to 90 when infected. |
| T1543.004 Launch Daemon |
MalwareCOATHANGER | COATHANGER will create a daemon for timed check-ins with command and control infrastructure. |
| T1564.001 Hidden Files and Directories |
MalwareCOATHANGER | COATHANGER creates and installs itself to a hidden installation directory. |
| T1573.002 Asymmetric Cryptography |
MalwareCOATHANGER | COATHANGER connects to command and control infrastructure using SSL. |
| T1574 Hijack Execution Flow |
MalwareCOATHANGER | COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`. |
| T1574.006 Dynamic Linker Hijacking |
MalwareCOATHANGER | COATHANGER copies the malicious file |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.